[Buildroot] [PATCH 6/8] package/rpm: security bump to 4.14.2.1

Thomas Petazzoni thomas.petazzoni at bootlin.com
Fri Mar 29 07:34:06 UTC 2019


On Thu, 28 Mar 2019 21:28:52 +0100
Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:

> - Remove first and second patches (already in version)
> - Remove third and fourth patches (not needed since:
>   https://github.com/rpm-software-management/rpm/commit/245b5a3b4b6d616adf47361137987e90f8dab22c)
> - Add hash for license file
> - Drop autoreconf (as configure.ac is not patched anymore)
> - Use new --with-crypto option
> - Restrict symlink following on installation (CVE-2017-7500,
>   CVE-2017-7501)
> 
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>

Can this be applied as PATCH 1/8 ? Indeed, we will want this security
bump in the LTS release, but not all the patches before it.

Ideally, this patch should be first in the series.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


More information about the buildroot mailing list